Why Authentication Assurance Matters

Authentication has never been stronger.

Today we have Multi-Factor Authentication, passwordless sign-in, passkeys, FIDO2 security keys and Conditional Access policies capable of enforcing phishing-resistant authentication across an organisation.

Yet organisations continue to suffer account compromise.

The problem is rarely that authentication is missing.

The problem is that the level of authentication assurance doesn’t always match the value of the identity being protected.

Authentication isn’t the objective

When a user signs in, the goal isn’t simply to prove they know a password or possess a device.

The real objective is to establish sufficient confidence that the person requesting access is genuinely the person they claim to be.

That confidence is what we call authentication assurance.

For many users, passwordless authentication using Microsoft Authenticator may provide more than enough assurance.

For others, particularly those capable of changing Conditional Access policies, creating Global Administrators or accessing sensitive organisational data, the same authentication experience may not provide the level of operational assurance required.

Not every identity carries the same risk

One of the biggest mistakes organisations make is assuming every identity should authenticate in exactly the same way.

In reality, identities have very different levels of organisational impact.

A compromised receptionist account is concerning.

A compromised Helpdesk Administrator account is more serious.

A compromised Exchange Administrator account could expose every mailbox.

A compromised Global Administrator could result in complete control of the tenant.

The authentication protecting those identities should reflect that difference.

Higher impact identities deserve higher assurance authentication.

Assurance is about confidence

It’s important to understand that authentication assurance isn’t simply about stronger technology.

It’s about increasing confidence.

Confidence that:

  • The correct individual is signing in.
  • The authentication method hasn’t been accidentally shared.
  • Credentials cannot easily be reused on another device.
  • Authentication cannot be silently approved by mistake.
  • Operational processes support secure administration.

Technology contributes to that confidence.

So do good operational practices.

Convenience has a cost

Throughout my career I’ve found that convenience is often the biggest driver behind authentication decisions.

People naturally choose whatever is easiest.

One device for everything.

One authentication method for every account.

One sign-in experience regardless of privilege.

It’s understandable.

Unfortunately, convenience doesn’t always align with security.

Sometimes introducing a small amount of friction dramatically increases assurance.

The goal isn’t to make authentication difficult.

The goal is to ensure the friction matches the impact of the identity being protected.

Modern authentication gives us choices

Microsoft Entra now provides multiple authentication options.

Passwords.

Multi-Factor Authentication.

Microsoft Authenticator passkeys.

Platform passkeys.

Synced passkeys.

Dedicated FIDO2 security keys.

Temporary Access Pass.

Authentication Strengths.

Conditional Access.

Each has strengths.

Each has limitations.

None of them are automatically the right answer for every identity.

Choosing the right authentication method requires understanding the level of assurance each provides.

Authentication Assurance is a design decision

There isn’t a single authentication method that every organisation should deploy.

Instead, authentication should become part of your identity architecture.

Consider:

  • The business impact if an identity is compromised.
  • The likelihood of phishing or social engineering.
  • Regulatory or compliance requirements.
  • Operational practicality.
  • Budget.
  • User experience.

Good authentication design balances all of these factors.

Looking beyond technology

One of the themes throughout this series is that authentication is about much more than technology.

Strong authentication depends on:

  • Identity
  • Device
  • Authentication method
  • Administrative environment
  • Conditional Access
  • Operational processes

The most secure authentication method in the world can still be undermined by poor operational practices.

Likewise, good operational design can significantly increase assurance without introducing unnecessary complexity.

Authentication assurance is about understanding the whole picture.

What’s Next?

Now that we’ve established why authentication assurance matters, the next question is how we arrived here.

In the next article we’ll explore the evolution of authentication, from passwords and traditional Multi-Factor Authentication through to modern passwordless authentication, passkeys and phishing-resistant credentials, and how each step has improved both security and user experience.